<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic High CPU utilization on Amp on Linux in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3313607#M4750</link>
    <description>&lt;P&gt;Hi. We see high CPU utilization on all of our Linux systems (Mix of RH 6 and CentOS 6 ). Have tried upgrading to the latest connector (1&lt;SPAN&gt;.6.0.536)&lt;/SPAN&gt;&amp;nbsp; - but that did not solve the problem. Have tried installing on a few systems - same result. We are afraid to deploy on heavily utilized system if its going to eat all of the CPU... Does it always take all non used CPU&amp;nbsp; at a given time?&amp;nbsp; We see it using up to 96% sometimes. Any information would be appreciated. Thanks&lt;/P&gt;</description>
    <pubDate>Sat, 09 Mar 2019 01:46:10 GMT</pubDate>
    <dc:creator>avidavidowitz</dc:creator>
    <dc:date>2019-03-09T01:46:10Z</dc:date>
    <item>
      <title>High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3313607#M4750</link>
      <description>&lt;P&gt;Hi. We see high CPU utilization on all of our Linux systems (Mix of RH 6 and CentOS 6 ). Have tried upgrading to the latest connector (1&lt;SPAN&gt;.6.0.536)&lt;/SPAN&gt;&amp;nbsp; - but that did not solve the problem. Have tried installing on a few systems - same result. We are afraid to deploy on heavily utilized system if its going to eat all of the CPU... Does it always take all non used CPU&amp;nbsp; at a given time?&amp;nbsp; We see it using up to 96% sometimes. Any information would be appreciated. Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2019 01:46:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3313607#M4750</guid>
      <dc:creator>avidavidowitz</dc:creator>
      <dc:date>2019-03-09T01:46:10Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3313975#M4762</link>
      <description>&lt;P&gt;A couple of questions:&lt;/P&gt;
&lt;P&gt;1. Is your policy utilizing "exclusions?"If yes, are you using a custom one or the Cisco Recommended?&lt;/P&gt;
&lt;P&gt;2. Do you have another A/V, EPP running on those hosts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 19:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3313975#M4762</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2018-01-18T19:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3314064#M4777</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/274561"&gt;@nspasov&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;A couple of questions:&lt;/P&gt;
&lt;P&gt;1. Is your policy utilizing "exclusions?"If yes, are you using a custom one or the Cisco Recommended?&lt;/P&gt;
&lt;P&gt;2. Do you have another A/V, EPP running on those hosts?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;No exclusions - also, no other A/V or EPP running&lt;/P&gt;</description>
      <pubDate>Thu, 18 Jan 2018 21:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3314064#M4777</guid>
      <dc:creator>avidavidowitz</dc:creator>
      <dc:date>2018-01-18T21:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3314394#M4787</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for a detailed analysis, please open a ticket with following logs inc.&lt;/P&gt;
&lt;P&gt;/var/log/cisco/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can give few advice's at this moment:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;get the agent PID ps aux | grep -i amp or stop the daemon with "initctl stop cisco-amp"&lt;/LI&gt;
&lt;LI&gt;kill the agent process and see if it has any effect on high cpu. If the CPU gets healthier, we can help you to tune exclusions for most checked file cloud query lookups.&lt;/LI&gt;
&lt;LI&gt;Policies - File Mode make sure you do not have "On Execute Mode" set in your policy.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 11:08:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3314394#M4787</guid>
      <dc:creator>David Janulik</dc:creator>
      <dc:date>2018-01-19T11:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3314732#M4793</link>
      <description>&lt;P&gt;I have the feeling the high CPU is due to the fact that you are not using exclusions. You can try this:&lt;/P&gt;
&lt;P&gt;1. Copy your existing Linux policy&lt;/P&gt;
&lt;P&gt;2. Attach the Default Exclusion set for Linux workstations&lt;/P&gt;
&lt;P&gt;3. Create a test group&lt;/P&gt;
&lt;P&gt;4. Attache the newly created policy&lt;/P&gt;
&lt;P&gt;5. Attach one of the workstations that is experiencing the high CPU utilization&lt;/P&gt;
&lt;P&gt;6. Test and see if this fixed the problem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jan 2018 18:58:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3314732#M4793</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2018-01-19T18:58:39Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3315155#M4801</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/274561"&gt;@nspasov&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;I have the feeling the high CPU is due to the fact that you are not using exclusions. You can try this:&lt;/P&gt;
&lt;P&gt;1. Copy your existing Linux policy&lt;/P&gt;
&lt;P&gt;2. Attach the Default Exclusion set for Linux workstations&lt;/P&gt;
&lt;P&gt;3. Create a test group&lt;/P&gt;
&lt;P&gt;4. Attache the newly created policy&lt;/P&gt;
&lt;P&gt;5. Attach one of the workstations that is experiencing the high CPU utilization&lt;/P&gt;
&lt;P&gt;6. Test and see if this fixed the problem&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;There are no default recommended exclusions for Linux:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118341-configure-fireamp-00.html#anc12" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118341-configure-fireamp-00.html#anc12&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Can you point me somewhere else?&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2018 21:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3315155#M4801</guid>
      <dc:creator>avidavidowitz</dc:creator>
      <dc:date>2018-01-20T21:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3315158#M4807</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/201848"&gt;@David Janulik&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for a detailed analysis, please open a ticket with following logs inc.&lt;/P&gt;
&lt;P&gt;/var/log/cisco/&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can give few advice's at this moment:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;get the agent PID ps aux | grep -i amp or stop the daemon with "initctl stop cisco-amp"&lt;/LI&gt;
&lt;LI&gt;kill the agent process and see if it has any effect on high cpu. If the CPU gets healthier, we can help you to tune exclusions for most checked file cloud query lookups.&lt;/LI&gt;
&lt;LI&gt;Policies - File Mode make sure you do not have "On Execute Mode" set in your policy.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Best Regards&lt;/P&gt;
&lt;P&gt;David&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Killing the agent drops CPU - it is for sure AMP related. I have no idea about default a default exclusion list - there doesn't seem to be anything listed for default exclusions on line:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118341-configure-fireamp-00.html#anc12" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/sourcefire-fireamp-endpoints/118341-configure-fireamp-00.html#anc12&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regarding File Mode - it's set to Passive&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2018 21:28:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3315158#M4807</guid>
      <dc:creator>avidavidowitz</dc:creator>
      <dc:date>2018-01-20T21:28:48Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3315160#M4812</link>
      <description>&lt;P&gt;Shoot you are right! I just checked my console and there is a default exclusion set for Linux workstations but it is blank &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; At this point I would suggest reaching out to TAC and have them troubleshoot the issue and perhaps suggest some recommendations around exclusions for Linux based deployments.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Jan 2018 21:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3315160#M4812</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2018-01-20T21:33:21Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3320348#M4815</link>
      <description>&lt;P&gt;So going through the logs we saw hundreds of hits to the following directories in a 15 second period and excluded them causing CPU to drop to 2-3%. I would love to know exactly what the default exclusions should be and if I am excluding anything that really shouldn't be from a a security perspective.....&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597860" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/bin/bash&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597864" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/bin/date&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597863" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/bin/df&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597865" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/bin/ps&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597866" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/home/observium/rrd&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597862" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/opt/cisco/amp&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597867" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/usr/bin/perl&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597861" class="imn-exclusion-name legacy-list-item-heading"&gt;Path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/usr/bin/php&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597869" class="imn-exclusion-name legacy-list-item-heading"&gt;Wildcard:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/proc/*&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597859" class="imn-exclusion-name legacy-list-item-heading"&gt;Wildcard:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/usr/bin/snmp*&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="imn-exclusion legacy-sidebar-list-item"&gt;
&lt;DIV id="exclusion-4597868" class="imn-exclusion-name legacy-list-item-heading"&gt;Wildcard:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;/usr/local/nagios/*&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;DIV class="imn-exclusion-name legacy-list-item-heading"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sun, 28 Jan 2018 07:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3320348#M4815</guid>
      <dc:creator>avidavidowitz</dc:creator>
      <dc:date>2018-01-28T07:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3379932#M4821</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have the exclusions set total 46 added i can see them in policy.xml file plus attached herewith is the file and process scan policy can you check and suggest any changes that can bring down the CPU usage on our oracle linux boxes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On execute mode is set to default Passive&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 10:52:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3379932#M4821</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2018-05-08T10:52:16Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3380250#M4826</link>
      <description>&lt;P&gt;Just looking at the exclusion policy&amp;nbsp;without seeing what's actually happening on the systems is unlikely to reveal very much. &amp;nbsp;The best way to resolve high CPU issues is generally via a TAC case. &amp;nbsp;The support engineer can help you collect and analyze usage information to determine the source of the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 08 May 2018 17:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3380250#M4826</guid>
      <dc:creator>brmcmaho</dc:creator>
      <dc:date>2018-05-08T17:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: High CPU utilization on Amp on Linux</title>
      <link>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3380603#M4828</link>
      <description>&lt;P&gt;Thanks i have raised a TAC case will post my findings here.&lt;/P&gt;</description>
      <pubDate>Wed, 09 May 2018 11:33:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/high-cpu-utilization-on-amp-on-linux/m-p/3380603#M4828</guid>
      <dc:creator>hrithiktej</dc:creator>
      <dc:date>2018-05-09T11:33:36Z</dc:date>
    </item>
  </channel>
</rss>

